#VU15451 Information disclosure in macOS - CVE-2018-3646

 

#VU15451 Information disclosure in macOS - CVE-2018-3646

Published: October 22, 2018 / Updated: October 31, 2018


Vulnerability identifier: #VU15451
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2018-3646
CWE-ID: CWE-200
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vulnerable software:
macOS
Software vendor:
Apple Inc.

Description

The vulnerability allows an adjacent attacker to obtain potentially sensitive information on the target system.

The weakness exists on the systems with microprocessors utilizing speculative execution and address translations due to an error in Hypervisor. An adjacent attacker can access information residing in the L1 data cache via a terminal page fault and a side-channel analysis.


Remediation

Update to version 10.14.1.

External links